<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logging levels in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/logging-levels/m-p/160215#M52248</link>
    <description>&lt;P&gt;Palo Alto is currently logging URLs which includes a path such as webserver.com/code.exe?id=4 but Palo is capable of logging a message that would display just the code.exe filename as well as a content type such as application/x-octet-stream or ms-executable.&amp;nbsp;&amp;nbsp;I would like to have&amp;nbsp;&amp;nbsp;these FILE events. Does anyone have insight into this for a palo beginner? Any and all help is appreciated!&lt;/P&gt;&lt;P&gt;Fields Required:&lt;BR /&gt;- Filename&lt;BR /&gt;- Content Type&lt;BR /&gt;- File Size&lt;BR /&gt;- Any reputation scoring&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2017 13:43:00 GMT</pubDate>
    <dc:creator>jerm1020</dc:creator>
    <dc:date>2017-06-08T13:43:00Z</dc:date>
    <item>
      <title>Logging levels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-levels/m-p/160215#M52248</link>
      <description>&lt;P&gt;Palo Alto is currently logging URLs which includes a path such as webserver.com/code.exe?id=4 but Palo is capable of logging a message that would display just the code.exe filename as well as a content type such as application/x-octet-stream or ms-executable.&amp;nbsp;&amp;nbsp;I would like to have&amp;nbsp;&amp;nbsp;these FILE events. Does anyone have insight into this for a palo beginner? Any and all help is appreciated!&lt;/P&gt;&lt;P&gt;Fields Required:&lt;BR /&gt;- Filename&lt;BR /&gt;- Content Type&lt;BR /&gt;- File Size&lt;BR /&gt;- Any reputation scoring&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 13:43:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-levels/m-p/160215#M52248</guid>
      <dc:creator>jerm1020</dc:creator>
      <dc:date>2017-06-08T13:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Logging levels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-levels/m-p/160226#M52249</link>
      <description>&lt;P&gt;Hi Jerm,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes you can do this with a file blocking profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First you will need to create a file blocking profile which can be done in the Objects tab then select file blocking on the left hand side menu.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Click add at the bottom to create a new profile then add in a rule to have the action 'alert' on all applications, file types etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Give the profile a name and click ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Create file blocking profile" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9597iEEBBA5290E17C236/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fb1.png" alt="Create file blocking profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Create file blocking profile&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to your security policies under the policies tab and select the policy in which your traffic is hitting. In the actions tab of the selected policy, you can choose your new file blocking profile from the drop down if you select profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Add file blocking to security policy" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9596i3AA63AD7B167FCF9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="fb2.png" alt="Add file blocking to security policy" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Add file blocking to security policy&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Click commit in the top right hand corner to push the changes down to the data plane and make them active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 13:55:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-levels/m-p/160226#M52249</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-06-08T13:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Logging levels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/logging-levels/m-p/161597#M52564</link>
      <description>&lt;P&gt;Thanks Ben! So this profile when applied should include the Information&amp;nbsp;Fields Required such as:&lt;BR /&gt;- Filename&lt;BR /&gt;- Content Type&lt;BR /&gt;- File Size&lt;BR /&gt;- Any reputation scoring&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking to apply this to the perimeter edge mostly to see if someone is downloading exe. files from the web. Much appreciate the prompt response and assist on this. Thank you again!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 15:14:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/logging-levels/m-p/161597#M52564</guid>
      <dc:creator>jerm1020</dc:creator>
      <dc:date>2017-06-16T15:14:37Z</dc:date>
    </item>
  </channel>
</rss>

